Vulnerability Details CVE-2021-20028
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
Exploit prediction scoring system (EPSS) score
EPSS Score 0.859
EPSS Ranking 99.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
Ransomware Campaign
Known
Products affected by CVE-2021-20028
-
cpe:2.3:h:sonicwall:sma_210:-
-
cpe:2.3:h:sonicwall:sma_410:-
-
cpe:2.3:h:sonicwall:sma_500v:-
-
cpe:2.3:h:sonicwall:sra_1600:-
-
cpe:2.3:h:sonicwall:sra_4600:-
-
cpe:2.3:h:sonicwall:sra_va:-
-
cpe:2.3:o:sonicwall:sma_210_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_210_firmware:9.0.0.10
-
cpe:2.3:o:sonicwall:sma_410_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_410_firmware:9.0.0.10
-
cpe:2.3:o:sonicwall:sma_500v_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sma_500v_firmware:9.0.0.10
-
cpe:2.3:o:sonicwall:sma_500v_firmware:9.0.0.9-26sv
-
cpe:2.3:o:sonicwall:sra_1600_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sra_4600_firmware:8.0.0.0
-
cpe:2.3:o:sonicwall:sra_va_firmware:8.0.0.0